
There is an easy enough test for AI data privacy in Australian retail: should an AI system be on the shop floor if the retailer cannot account for what customer information it is making use of, where it is headed and the reason for it? The answer is no. On top of that, there are the matters of customer consent, the risks inherent in automated decisions, third-party providers and data security to factor in, all under the Privacy Act 1988 and the Australian Privacy Principles.
Daniel Crowe here. One has to have been around customer-facing businesses long enough to appreciate that trust is a slow process to build and can be undone by one ill-advised exchange. A customer will put in a loyalty app without thought but put up a different front when an algorithm is quietly altering the price or a camera is doing some facial analysis. The sensible course is not to forgo AI altogether but to involve a human when it counts, be more forthcoming and rely on less data.
Deploying AI With Trust
The right application of retail AI will see better stock planning, personalised recommendations, fraud detection, service and personalized e-commerce experiences. Yet if a business is in the habit of taking more than it has any need for, it can make a nuisance of itself over privacy with the likes of purchase data and browsing history.
A good privacy programme is in place before you even start procurement. Do not view an AI project as just another piece of software to buy, but as a question of customer trust. Map your data, put the purpose to the test and make a call on what is not to be collected at all.
An Understanding Of Data Flows
Make a list of your sources: from point-of-sale and CCTV to website cookies, marketing pixels, social media, mobile apps and any transcripts from customer service. Note what identifies a person and what would do so were it to be put together with another set of data.
You might find health or financial strain in the purchase data of a customer; browsing history can tell you of sensitive interests even in the absence of a log in. What seems innocuous on its own is personal information once you have an email address or loyalty number to match it against.
Doing Right By The Privacy Act
For much of the organisations in Australia that deal with personal information the framework is the Privacy Act 1988 and the Australian Privacy Principles. But the onus is on the retailer and will vary with its size, activities and data practices, so any compliance review needs to reflect the realities of the business structure. The guidance from the Office of the Australian Information Commissioner is a sound place to begin; their 13 principles will cover everything from open management and collection to security and correction.
Collection Should Have A Purpose
Do not be in the habit of re-purposing personal information for some AI experiment. If a phone number was taken for account recovery in a loyalty scheme, it does not follow that it should be handed over to an external generative AI or used in personalised pricing.
Plain speaking is called for in a privacy notice. “We may use information to improve services” is hardly illuminating for the customer. Put down the categories of data and why they are being used, which providers are involved, any transfers overseas and the means to lodge a complaint. And de-identification is not a panacea as some think; strip away a name and there is still risk if a rare purchase or location trail can be traced back to the individual.
Hold Back On Collecting
It is true that AI is sold as being more capable with greater volumes of data but that is no reason to run every customer record through a model. Minimise the data and you will have fewer costs and vendor risks, and less trouble at the service desk. Ask yourself whether the use case would hold up if a particular field were gone tomorrow; if it would, leave it be unless there is good cause to keep it.
Useful Versus Excessive
| AI use case | Potential data | Privacy question | Safer practice |
|---|---|---|---|
| Product recommendations | Browsing history and purchases | Was the customer made aware of the profiling? | Give the customer some control and use only what behavioural signals are necessary. |
| Demand forecasting | Sales, inventory and location data | Is personal information actually needed? | Use aggregated or de-identified data when that will do. |
| Customer service chatbot | Order details and messages | Could a vendor be privy to something sensitive? | Filter the inputs, put limits on retention and have a process to escalate anything that is complex. |
| Fraud detection | Account behaviour, device data and transactions | Has a bona fide customer been blocked in error? | Put review processes in place to correct for this and make the reasoning behind decisions plain. |
| Facial recognition | Face images and biometric templates | Is the collection proportionate and lawful? | Get informed consent as needed and go with the least intrusive option. |
Be careful with Biometric Data
In Australia’s retail sector, facial recognition is among the more sensitive applications of AI. A compromised face is not like a password which can be reset. For this reason retailers should regard faceprints and other biometrics as high-risk and subject them to firm governance.
Having a camera in a public shop does not absolve one of privacy duties. What is being captured by it? Is there software at work analysing it or creating a biometric template? How long is the information kept and is it put up against a watchlist? These are the things to consider.
Set a High Bar
There should be documentation of the purpose, any false positive risk, access controls, the deletion process and so forth before a facial recognition system is put out. One might find that transaction monitoring or a well trained member of staff will do as well with less intrusion than an AI system.
Do not let customers be in the dark. Signage must be in evidence to tell them AI is being used and where they can find out more or what their options are. A small sticker on the ceiling is no substitute for transparency; it is merely privacy theatre in a hi-vis vest.
On Consent And Decisions
Where consent is required as a matter of law or is the legal basis of choice, it has to be given freely and be specific. No one should be expected to part with personal details unconnected to the matter at hand to purchase something or get some assistance at a counter.
Automated decision-making in Australia also warrants thought from retailers. An AI putting forward a jumper is not the same as one that alters a price, denies a refund or puts a hold on an account on suspicion of fraud.
Hold Humans to Account
For decisions of consequence there must be a clear path to review. Make it known to the customer if automation has had a material bearing on the result and give them a way to contest it. Staff should be able to overrule the system and the human reviewer ought to have the authority and the facts to do more than rubber-stamp what the machine says.
Then there is personalised pricing. When two shoppers are quoted differently on the strength of their location or loyalty or some inference as to how much they are willing to pay, the retailer would do well to look at the fairness of it and the reputational and consumer law risks. “The algorithm did it” is not a defence that will put a customer at ease.
Vendors and Transfers
A third-party AI vendor may have subcontractors you have never come across, keep prompts to better its service or do its processing outside of Australia. The contract may say the provider is on top of security but the retailer is still answerable for the arrangement. This holds for cloud hosting, generative AI, recommendation engines and the like. OpenAI or ChatGPT have their uses in a controlled workflow but there should be an approved process in place before staff put customer records into a public tool.
Due Diligence
When vetting an AI vendor look at the audit rights, the security and training practices, the data locations and the like. Can the provider isolate information by tenant or honour a deletion request? Are the files and prompts being used for model training?
Pay particular heed to any transfer of data overseas. You need to know which countries are receiving the information and what contractual safeguards are in effect and what the Australian Privacy Principles dictate. Even data in Australia is not without risk but a transfer you have not identified is impossible to manage.
Everyday Protection of Customer Information
Policies should be of a length to be of use and the training practical so that when there is a chatbot down or a queue out the door your staff can adhere to them. Access is to be restricted to what the job demands.
I would put it bluntly: a team member should not have to wonder if he can copy some customer data into an AI tool. The answer, and what is off limits, should be apparent before the pressure is on.
Operationalise Security
- AI systems and the customer databases attached to them should be secured with strong logging, encryption, multi-factor authentication and role-based access.
- Where you can set a limit on retention and have it auto-deleted, do so and then verify it has been done.
- Keep unapproved marketing platforms, browser extensions and generative AI tools from any sensitive information.
- Before a model is put out there, it should be put through its paces for bias, prompt injection, data leakage, any propensity to give inaccurate or unsafe recommendations.
- Have an incident plan in place that will see you through containment and investigation, as well as customer and regulatory notification when the occasion calls for it.
Then there are marketing pixels and third-party tracking to be reviewed on their own merits. A tag put in to measure a campaign can pass along account-linked information, product identifiers or page visits to some other organisation. Put in hand a register of your tags, vendors and where the data is going; if something does not have a documented purpose, do away with it.
A Practical Compliance Check
Australian retailers setting up a new AI project or having a look at one already in place will find the checklist below useful. While it is no replacement for legal counsel, it has a way of revealing the sort of gaps that become problems down the track.
- Start by defining the use case and putting the customer benefit on paper.
- You will want to map all inputs and outputs, users, vendors, storage and any overseas transfer.
- Make a distinction between personal and sensitive information, biometric and de-identified data.
- See if your collection and disclosure are in keeping with the Privacy Act 1988 and the Australian Privacy Principles.
- Your privacy notices should be updated to a level of plainness so a customer does not need to have studied law to make sense of the system.
- Go with the least intrusive means of doing things and question whether you really need the personal information.
- Look at what consent and opt-out options are on offer to those who would rather not be part of it.
- Test for accessibility, false positives, accuracy and bias and how it might impact a vulnerable customer.
- Do your due diligence on the AI vendor and have a contract that covers security, audit, deletion and breach support.
- Before launch, get your controls set for retention, access and incident response.
- There should be a human in the loop for anything of consequence and a straightforward way to make corrections.
- And make a record of approvals, complaints, changes and testing results.
If the review is to be done in a day, concentrate on the live data map, the vendor terms, the privacy notice and the use case carrying the most risk. Should the project call for biometric data or a decision that could put a customer at a material disadvantage, hold off on launching until you have finished your assessment.
Some Common Privacy Questions
In retail one finds privacy matters are inextricably linked with digital identity, data hosting and the wider AI policy. What follows is an attempt to distinguish what is in the retailer’s control from what is left to the customer, the provider’s architecture or government.
Can I Refuse A Digital ID In Australia?
Do not put it past a customer to eschew a digital ID for a routine shop. It is a matter of the service and the verification process. A retailer ought to make clear why identification is being asked for and proffer a lawful alternative; there is no need to amass more identity data because a digital one is available.
Does Australia Have AI Data Centres?
The infrastructure is here for cloud and AI, but the moniker “Australian data centre” is no guarantee that a subcontractor process or backup is not leaving the country. One would be better served to read the fine print of the provider’s contract and check the data flows than to take a sales label at face value.
Is Australia Pushing For Digital ID?
Policy and digital identity arrangements are being put in place, but a retailer still has to determine what applies to its service. While it spares one the tedium of repeated document handling, there are privacy risks if too much is shared or held.
What Of The New Privacy Laws Due In 2026?
Reform comes in many forms: legislation, guidance, enforcement. Do not make a compliance claim on the strength of a rumour or a proposal that is not yet law. Get some current legal advice and watch the official announcements.
Can Retail AI Make Use Of Purchase Data?
Possibly, but only in accordance with the notice, context and other legalities. Just because a customer handed over the data in the course of a transaction does not make it harmless. Be clear about profiling and let the customer have some say.
Privacy In Retail
There is a case for AI to make for a more efficient operation and a personalised experience of real value. But it is not an excuse to hoard every click and message in the off chance a model can be made to do something clever with it later.
The best way to handle AI privacy in this market is to be practical: minimise what you collect, test the risks, keep the vendors in check and ensure humans are answerable. That is how you put together an e-commerce experience without making a walking data parcel of your customers.
Daniel Crowe would put it to you in simple terms: can the customer put questions to the system and trust what he is told? If the answer is no, the retailer is not done with the project yet, billy or not.